WordPress Hacked? The 7-Step Recovery Protocol (2026)
Quick answer: Hacked WordPress recovery in 7 steps: isolate the site, scan to confirm, clean or restore from a pre-infection backup, rotate every credential, reinstall core, request Google review, then harden so it doesn't happen again. Act within hours — Google blacklists fast.
Step 1-2: Isolate and Confirm
Take the site offline or into maintenance mode — a live hacked site spreads malware to visitors and gets blacklisted. Then confirm the infection: run a Wordfence scan, check for unknown admin users, look for recently modified files you didn't touch, and check Search Console's Security Issues report. Document what you find — you'll need it for cleanup.
Step 3: Clean — Two Paths
| Path | When | Risk |
|---|---|---|
| Restore clean backup | Backup predates infection | Lose recent content; backup may be infected too |
| Manual cleanup | No clean backup exists | Miss one backdoor, reinfected in days |
Manual cleanup means: reinstall WordPress core from wordpress.org (fresh wp-admin, wp-includes), replace plugins/themes with fresh copies from official sources, scan uploads for injected PHP, and audit the database for malicious posts and admin users. Miss one backdoor and you're reinfected within days — when in doubt, professional cleanup ($100-300) beats a second hack.
Step 4-5: Rotate Everything, Reinstall Core
Every credential changes: hosting panel, wp-admin (all users), database, FTP/SFTP, API keys, and your WordPress salts in wp-config.php (invalidates all sessions). Do it from a device you've scanned — if your laptop has the keylogger, new passwords don't help.
Step 6-7: Google Review and Hardening
Clean first, then request review in Search Console — Google re-scans in 24-72 hours. Then close the entry point: enable auto-updates, set up two-factor authentication, install a security plugin, and work through our 15-step security checklist. If the hack came through a vulnerable plugin or theme, check whether your page builder or an abandoned plugin was the vector.
Hosting That Helps Prevent This
Bluehost includes malware scanning, free SSL, and account isolation — plus free migration if your current host was the weak link.
Get Bluehost from $2.95/mo →What are you building?
Tell us about your project so we can match the perfect hosting plan.
Hosting Cost Calculator
See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.
Used to calculate transaction fees (Shopify charges 2% on sales)
Frequently Asked Questions
What should I do first if my WordPress site is hacked?
Isolate it — put the site in maintenance mode or take it offline, then change all passwords (hosting, wp-admin, database, FTP) from a clean device. Speed matters: malware spreads and Google blacklists within hours.
How do I know if my WordPress site is hacked?
Common signs: Google 'This site may be hacked' warnings, sudden traffic drops, unknown admin users, redirected visitors, strange files or code injections, hosting suspension notices, and outbound spam emails from your server.
Can I clean a hacked WordPress site myself?
Yes if you're technical — restore from a clean backup, or manually remove malicious files after a Wordfence/Sucuri scan, reinstall core from wordpress.org, and rotate every credential. If the hack persists or you're unsure, professional cleanup (~$100-300) is worth it.
Will restoring a backup remove the hack?
Only if the backup predates the infection — malware often sits dormant for weeks. Scan the backup before restoring, and still rotate all credentials afterward since the entry point (usually a stolen password or vulnerable plugin) remains open otherwise.
How do I remove a Google blacklist warning?
Clean the site completely first, then request a review in Google Search Console (Security Issues report). Google typically re-scans within 24-72 hours. Requesting review before cleaning just delays removal.
How do I prevent getting hacked again?
Find the entry point first — check for vulnerable plugins, weak passwords, or missing 2FA. Then: auto-updates on, 2FA on all admin accounts, a security plugin, off-server backups, and a host with account isolation. Our security checklist covers all 15 steps.
Ready to launch?
Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.
Related Articles
Premium Domain Names in 2026: Pricing, Valuation & Buying Guide
What premium domains cost, how they're valued, where to buy them, and when a $2,000 domain beats a $12 one. The complete aftermarket guide.
What Is Domain Privacy? WHOIS Protection Explained (2026)
Domain privacy hides your name, address and email from public WHOIS lookups. Who offers it free, who charges $10/yr, and whether you actually need it.
Subdomain vs Subdirectory for SEO in 2026: The Definitive Answer
blog.example.com or example.com/blog? What Google actually says, what the data shows, and the 4 cases where a subdomain is genuinely correct.